
The Hacker News
July 20, 20261 min read
A malware operator left its delivery server wide open, and Rapid7 pulled down the whole toolkit: 1,048 files spanning lure templates, filename-spoofing tests, execution experiments, droppers, builder notes, and two campaign chains. One was already live against Windows users in Mexico, delivering an infostealer through a fake government ID-lookup site over WebDAV. What makes it more than a
Read what's here, then head to the original whenever you're ready - never required.
Continue Reading on The Hacker NewsNew ENCFORGE Ransomware Targets AI Model Files in Langflow RCE Attack
The Hacker News July 21, 2026